Back to Malware Drops

be0abc2136f0ffa65cf9ae0cb9293133170ac990ae44d3f701671a796fa9abb4

MD55e60c5e1f91deb0f701c9e8d51eae5d6
SSDEEP
File Typetext/x-script
Size2.0 KB
Sources2
Downloads0
First SeenJul 5, 2019
Last SeenJul 5, 2019
Download sample (.zip, password: infected)

Live malware — handle only in an isolated analysis environment.

Originating Attacks

Honeypot sessions that dropped this sample. Drop URLs are defanged; commands are shown verbatim and are not links.

Indicators of Compromise

Values are defanged (e.g. hxxp://, [.]) — not live links.

ipv4 (1)

  • 54[.]39[.]167[.]102

url (13)

  • hxxp://54[.]39[.]167[.]102/apache2;
  • hxxp://54[.]39[.]167[.]102/bash;
  • hxxp://54[.]39[.]167[.]102/cron;
  • hxxp://54[.]39[.]167[.]102/ftp;
  • hxxp://54[.]39[.]167[.]102/ntpd;
  • hxxp://54[.]39[.]167[.]102/nut;
  • hxxp://54[.]39[.]167[.]102/openssh;
  • hxxp://54[.]39[.]167[.]102/pftp;
  • hxxp://54[.]39[.]167[.]102/sh;
  • hxxp://54[.]39[.]167[.]102/sshd;
  • hxxp://54[.]39[.]167[.]102/telnetd;
  • hxxp://54[.]39[.]167[.]102/tftp;
  • hxxp://54[.]39[.]167[.]102/wget;